
The Reserve Bank of India has released a discussion paper proposing significant changes to digital payment systems to combat fraud. According to ABP Live, the central bank proposes a one-hour mandatory delay on UPI payments above ₹10,000 specifically for person-to-person transfers. Under option 1, banks would be required to hold transfers above ₹10,000 for one hour at the payer's end before executing them. During this window, customers would retain the option to cancel, and if a transaction appears suspicious, banks would be required to seek reconfirmation from the payer before proceeding. The proposed delay may be implemented at the sender's end, the recipient's end, or both, as per The Times of India. Merchant payments, e-mandates, NACH transactions and cheques would be exempt from the delay requirement. The ₹10,000 threshold is deliberate, as such transactions account for around 45% of fraud cases by volume and represent nearly 98.5% of total fraud value, according to data from the National Cyber Crime Reporting Portal (NCRP). The RBI explains that "a short delay can act as a preventive control by disrupting the fraudster's psychological influence over the victim," allowing users to cancel transactions and providing banks a window to flag suspicious activity.
The RBI discussion paper introduces several protective measures for vulnerable users. For senior citizens and persons with disabilities, the proposal includes option 2, requiring citizens aged 70 and above and persons with disabilities to nominate a "trusted person" whose authentication would be mandatory for transfers above ₹50,000. Nearly 92% of fraud losses by value occur above this threshold, often through social engineering and impersonation scams. The central bank notes that most frauds are now "authorised push payment" (APP) cases, where users themselves transfer money after being manipulated through impersonation, coercion or social engineering. The paper also suggests implementing a 'kill switch' to instantly block all digital transactions in case of suspected fraud. Customers will gain greater control through option 4, which provides customers with controls consisting of a 'switch on/off' facility for any digital payment mode as well as for setting limits for different transaction types at the account level. Additionally, customers may be provided with a single facility to disable all digital payment transactions from the account at one stroke. These features may be made available through mobile banking, internet banking, bank branches and IVR services.
While the RBI's proposal aims to strengthen digital payment security, experts have raised concerns about potential disruptions to the payment ecosystem. CA Chandni Anandan from ClearTax noted that while the one-hour cooling period is a constructive step toward strengthening fraud prevention, it may introduce friction for time-sensitive transactions and could have implications for liquidity and statutory timelines, such as tax payments or vendor payouts linked to compliance deadlines. Hitesh Agrawal from Them Consulting warned that the proposed one-hour payment freeze risks overcorrecting, treating every user as a potential victim of fraud, and suggested that payments should pause only when something feels off, not when it feels familiar. Experts have identified several potential risks including reduced payment speed, delayed settlements, impact on emergency transactions, business cash flow disruptions, and potential adaptation by fraudsters to split transactions into smaller amounts.
According to The Times of India, banks will need to implement comprehensive fraud prevention systems. The proposed changes require banks to tighten due diligence by linking the level of activity in an account to the customer's profile. For instance, accounts with low verified income may face limits on how much money they can receive unless additional checks are completed. To crack down on 'mule' accounts used by fraudsters to receive and launder stolen funds, the RBI has proposed option 3, capping annual aggregate credits into individual and small business accounts at ₹25 lakh. Amounts beyond this threshold would be held as "shadow credit" accessible only after the account holder satisfies the bank about the transaction's legitimacy. If no justification is provided within 30 days, the funds would be returned to the sender. The central bank acknowledges that such measures may "conflict with the core design principle of immediacy of digital payments," but stressed the need to prioritise safety amid rising fraud risks.
A key finding from the RBI research indicates that most frauds now result from human vulnerability, as reported by The Times of India. The growth of digital payments has amplified this risk, making it crucial to implement protective measures. The discussion paper represents the central bank's effort to balance convenience with security in India's rapidly expanding digital payment ecosystem. Digital transaction volumes have increased 38-fold, while reported fraud cases have surged from 2.6 lakh in 2021 to 28 lakh in 2025 - with the value of fraud jumping from ₹551 crore to nearly ₹22,931 crore over the same period, driven by deepfakes, fake call centres, and mule account networks. The RBI notes that "fraudsters are deploying various tactics, such as bogus call centres, deepfake-driven impersonation scams and mule account networks. Almost all sections of society, especially the vulnerable groups such as senior citizens have fallen prey to such Authorised Push Payment Frauds (APP frauds)." Therefore, there is an urgent need to put in place systems and processes to address these issues. Digital payments comprise credit and debit cards, the Unified Payments Interface (UPI), Immediate Payment Service (IMPS), National Electronic Funds Transfer (NEFT), Real Time Gross Settlement (RTGS), mobile wallets, and net banking.
Comments on the RBI discussion paper are open until May 8, 2026, providing stakeholders with adequate time to provide feedback on the proposed measures. The central bank's initiative comes against the backdrop of an explosion in both digital payments and fraud, with the proposed measures aiming to protect people as digital payments and fraud cases surge in India's rapidly expanding digital payment ecosystem. The discussion paper, titled "Exploring safeguards in digital payments to curb frauds," outlines four possible safeguards to address the growing threat of digital payment fraud across all sections of society, particularly vulnerable groups. The RBI emphasizes that "a typical fraud through digital payments may not involve technical compromise of systems, but mostly through manipulation of users through social engineering, coercion, or impersonation. Victims, acting under deception, themselves initiate and authenticate transactions, leading to 'authorised' push-payment (APP) frauds." The measures were first flagged in the February policy statement, and the final framework will depend on feedback from stakeholders. The central bank acknowledges that while the proposed moves aim to improve financial transparency, security and boosting digital transaction systems, they might introduce new problems for users.